Grok apps, Grok Bot and integrations — product surface (not API)
Status: product documentation only (DOCUMENTED); none of these surfaces exposes a public REST API on api.x.ai (Grok Bot mentions an "Admin API" section for Cursor-dashboard admins; Grok Business admin is console-only). Nothing here was live-tested.
Sources: Grok overview · Grok FAQ · Connectors · connector guides (gmail-google-calendar, google-drive, onedrive, outlook, microsoft-teams, sharepoint, salesforce, custom-mcp-tunneling) · Grok Business user guide · License & user management · Connector management · Organization management (SSO/SCIM) · Grok Bot and its 19 sub-pages · HubSpot MCP setup · docs.x.ai overview · Community integrations.
Last verified: 2026-09-18 (docs snapshot sources/xai/pages/{grok,grok-bot,integrations}/**).
Product map
| Product | What it is | Access / plans | Developer surface |
|---|---|---|---|
| Grok (grok.com, iOS, Android, and X) | xAI's assistant: chat, Grok Imagine images/video, voice, file uploads, connectors | Free tier; SuperGrok / SuperGrok Heavy (weekly usage allowance, Extra Usage Credits, Auto Top Up); X-account linking | None (consumer). Same models are on api.x.ai. |
| Grok Business / Enterprise | Team workspaces on grok.com with enterprise ToS, sharing limited to licensed members, custom retention (Enterprise) | Licenses bought/assigned in console.x.ai (Grok Business overview); SSO (SAML/OIDC) + SCIM directory sync with role → team/permission/license mapping | Console only; sharing policy ladder Private → Team → Organization → Public (public links for conversations only; projects/skills cap at Organization) |
| Connectors | Grok reaching external data inside a chat: built-in OAuth connectors (Gmail & Google Calendar, Google Drive, OneDrive, Outlook Mail & Calendar, Microsoft Teams, SharePoint, Salesforce), a catalog of pre-configured OAuth connectors, and custom MCP connectors (bring your own public MCP server; local servers need a tunnel) | All users at grok.com/connectors; Business/Enterprise admins must provision in console (Team Read-Write permission) | MCP is the integration protocol: expose any tool via a Streamable-HTTP/SSE MCP server. Same protocol as the API's mcp tool and Grok Build. |
| Grok Bot (desktop macOS/Windows/Linux + iOS/Android) | Persistent "AI teammates" (Bots) with names/jobs/memory running on a shared cloud computer (browser, filesystem, terminal) per user; group chats between Bots; skills learned by demonstration; scheduled routines; approvals for sensitive steps | Included with paid Cursor individual plans and Cursor Teams; or link a SuperGrok / Plus / Heavy subscription; sign-in via Cursor account (SSO supported) | Enterprise admin controls in the Cursor dashboard (Grok Bot Computers recreate/terminate, Team Setup manifests, network policy, static egress IPs, TLS-inspecting proxies, private-network connectivity via scripts, identity/IdP app assignment, logging/audit, data residency). An "Admin API" heading exists under teams-and-enterprises (details not in the snapshot). |
| Integrations — HubSpot MCP | "xAI MCP" app in the HubSpot Marketplace giving Grok read-only access to CRM objects via a HubSpot connector | Grok subscription (SuperGrok recommended); HubSpot admin installs the app, user connects at grok.com/manage-connectors | MCP; no write scopes; data not stored by xAI |
| Grok Build | Coding agent CLI/TUI/ACP | see docs/xai/grok-build.md |
grok-build-0.1, grok-4.6 on the API |
Grok (consumer) — facts worth knowing for API users
- Limits are a single weekly allowance per plan spent across chat, Imagine, voice; when exhausted you can buy Extra Usage Credits (top-ups, Auto Top Up). API credits are separate and non-refundable; a "large invoice" on the account is usually API usage (FAQ).
- Grok Imagine in the app uses the same image/video families as the Imagine API (
grok-imagine-image-2.0,grok-imagine-video-1.5); voice in the app corresponds to the Speech-to-Speech API models. - Sign-in with X links subscriptions; Apple "Hide My Email" relay addresses cause activation issues (FAQ).
Grok Bot — model of operation (summary)
- Each member gets one hosted computer shared by all their Bots (files, browser sessions, logins); isolation between users is strict. Bots run in parallel, one computer-use task per Bot screen.
- Work is assigned by message; Bots use connectors when available and computer use otherwise; sensitive steps go to approvals (Auto Review available); "Take over" lets the human perform a step.
- Skills (reusable instructions; can be taught by recording up to 10 min of browser interaction) and routines (schedules / events) make work repeatable; a Marketplace offers connectors and packaged skills;
/references skills,@references Bots, groups, routines, connectors. - Templates share a Bot (public link or team-only). Duplicating copies profile, skills, routines but not memory or history.
- Enterprise: enable per team in Cursor dashboard, Team Setup manifests run scripts on computer creation (VPN/private network clients), network policy and static egress IPs, TLS proxy allow-lists, SSO/IdP app assignment, log/audit, data retention & residency, certifications (security page).
Connector setup gotchas (from the guides)
- Microsoft connectors (Teams, Outlook, OneDrive, SharePoint) need admin consent in Entra; SharePoint has site-scoping options; Salesforce needs a connected-app style approval.
- Custom MCP connectors must be reachable on the public internet; the tunneling guide covers exposing a local server.
- Removing a connector may delete indexed data associated with it.
Relationship to the API
The only programmable seam shared by these products and api.x.ai is MCP: the same server can back a grok.com connector, a Grok Bot connector, a Grok Build [mcp_servers.*] entry and the API's server-side mcp tool (chat/responses and the voice session.tools). Everything else (licenses, workspaces, Bots, routines) is managed in console.x.ai, grok.com or the Cursor dashboard.